MHDD Data Recovery & Forensics v15 - © 2009 MHDD 1 Hard Drive Kung Fu Magic MFT & File Based Imaging Data Recovery Forensics by Scott A. Moulton www.MyHardDriveDied.com.

Slides:



Advertisements
Similar presentations
Storage Management Lecture 7.
Advertisements

The Impact of Logical and Physical Fragmentation in a Virtual Environment Presented by Raxco Software, Inc. October 29, 2009.
COMP091 – Operating Systems 1
FAT vs NTFS.
Deleted File Recovery Tool Testing Results Jim Lyle NIST 2/21/13AAFS -- Washington 1.
BSD Partitions COEN 152/252 Computer Forensics. BSD Partitions Some BSD systems use IA32 hardware  Designed to co-exists with MS partitions.  Use DOS.
®® Microsoft Windows 7 for Power Users Tutorial 6 Optimizing Your Hard Disk.
DIT314 ~ Client Operating System & Administration CHAPTER 4 CONFIGURING HARDWARE DEVICES AND STARTUP PROCESS Prepared By : Suraya Alias.
Computer Forensics NTFS File System.
1 EXT4NTFS 6FAT32 Allocation method IndexedIndexed, by “runs”Linked File representation i-node (default size 256KB) MFT record (default size 1Kb) Chain.
Digital Forensics Module 11 CS /26/2004Module 112 Outline of Module #11 Overview of Windows file systems Overview of ProDiscover Overview of UNIX.
Lecture 10: The FAT, VFAT, and NTFS Filesystems 6/17/2003 CSCE 590 Summer 2003.
Connecting with Computer Science, 2e
FIRST COURSE Microsoft Access (Basics). XP Objectives Define the terms field, record, table, relational database, primary key, and foreign key. Learn.
File System Variations and Software Caching May 19, 2000 Instructor: Gary Kimura.
Wince File systems. File system on embedded File system choice on embedded is important –File system size can be an issue –Different media are used –
1 CSCD 496 Computer Forensics Lecture 7 File Systems – Windows Winter 2010.
Atola Insight Data Recovery Suite Dmitry Postrigan Atola Technology, Ukraine.
Hard Drive Formatting 1. Formatting Once a hard drive has been partitioned, there’s one more step you must perform before your OS can use that drive:
FDISK Partitioning Hard Disks. History We bought our new hard disk drive –Right size for BIOS and OS –Right connections (PATA/SATA) We installed our new.
Implementing Hard Drives Chapter 10
Digital Forensics Dr. Bhavani Thuraisingham The University of Texas at Dallas Lecture #12 Computer Forensics Analysis/Validation and Recovering Graphic.
A+ Guide to Managing and Maintaining Your PC Fifth Edition Chapter 9 Optimizing and Protecting Hard Drives.
1 Partitioning a Hard Drive ©Richard Goldman Revised January 8, 2001 Revised December 9, 2002.
Chapter Sixteen Data Recovery and Fault Tolerance.
Objectives Learn what a file system does
Mastering Windows Network Forensics and Investigation Chapter 7: Windows File Systems.
®® Microsoft Windows 7 for Power Users Tutorial 5 Comparing Windows 7 File Systems.
Disk Structures. CTEC 1102 Formatting a Disk Two parts to formatting a disk:  Low-level (physical) formatting  High level (logical) formatting Low-level.
BACS 371 Computer Forensics
Understand Disk Types LESSON Windows Server Administration Fundamentals.
Mastering Windows Network Forensics and Investigation Chapter 7: Windows File Systems.
Window NT File System JianJing Cao (#98284).
CLASSIFICATION OF VIRUSES By the end of our presentation you will know all about  File viruses  Boot sector virus  Marco virus.
Chapter 3 Managing Disk and File Systems. File Storage Basics Windows XP supports two types of storage Basic Dynamic Basic storage system Centers on partitioning.
MCTS Guide to Microsoft Windows Vista Chapter 4 Managing Disks.
Windows NTFS Introduction to Operating Systems: Module 15.
File Systems Dr John Cowell phones off (please). Q 1 Which of the following statements about NTFS is NOT true? a) NTFS uses 64 bit addressing. b) Supports.
Digital Forensics Dr. Bhavani Thuraisingham The University of Texas at Dallas Lecture #8 Guest Lecture September 21, 2009.
Mike Mabey CSE 598 – Spring 2010Nishanth Kotha Venkata A Robot for Google Wave.
1 Dynamic Drives ©Richard Goldman July 28, Basic Drive MBR VBRMFT VBRMFT VBRDirFAT C: (NTFS) D: (NTFS) E: (FAT32) MBR VBRMFT VBRMFT VBRDirFAT.
11 BACKING UP AND RESTORING SYSTEMS AND DATA Chapter 15.
Operating System Concepts and Techniques Lecture 18 Information management-2* FFS, UFS2, NTFS M. Naghibzadeh Reference M. Naghibzadeh, Operating System.
Chapter 18 ©2011 Eoghan Casey. Published by Elsevier Inc. All rights reserved. Forensic Examination of UNIX Systems.
FAT File Allocation Table
NTFS 5.0 By Jeffrey Richter and Luis Felipe Cabrera From the Microsoft Systems Journal Presented by Stylianos Paparizos.
Presented by Kofi Appiah Nuamah NTFS Forensics with Disk Explorer Project 3.1.
Windows Disaster Recovery.  NT/2K Emergency Repair Disk (nsg)  XP Automated System Recover (pg)  Or:  Reinstall and restore from backup.
Adding a Hard Drive. BIOS / UEFI The Unified Extensible Firmware Interface (UEFI) defines a software interface between an operating system and platform.
Digital Forensics Dr. Bhavani Thuraisingham The University of Texas at Dallas Lecture #8 File Systems September 22, 2008.
COEN 252: Computer Forensics Hard Drive Evidence.
Disk storage systems Question#1 (True/False) A track is divided into multiple units called sectors.
Hands-On Microsoft Windows Server 2008 Chapter 7 Configuring and Managing Data Storage.
Hyper-V Recovery Software Ideal Application to Get Data from VHD v2.1.
Windows 10 vs. 7 – Disk Drives NORTH TEXAS PC USER GROUP WINDOWS INSIDE-OUT SIG GLYNN BROOKS FEBRUARY 20, 2016.
Visit:  If you have lost important files, take a deep breath and rest assured that disk recovery software can likely help.
Silberschatz, Galvin and Gagne ©2011 Operating System Concepts Essentials – 8 th Edition Chapter 3: Windows7 Part 3.
Day 28 File System.
Advanced Computer Forensics
Efficient Drive forensics – and it’s free!
Computer Forensics NTFS File System.
Partitioning a Hard Drive
Chapter 3: Windows7 Part 3.
Chapter 5 Image Restoration.
COEN 252: Computer Forensics
Computer Forensics NTFS File System.
COEN 252: Computer Forensics
Understanding Forensic Images
FAT File System.
Causes And Solution To Recover Lost Partition Table.
Presentation transcript:

MHDD Data Recovery & Forensics v15 - © 2009 MHDD 1 Hard Drive Kung Fu Magic MFT & File Based Imaging Data Recovery Forensics by Scott A. Moulton

MHDD Data Recovery & Forensics v15 - © 2009 MHDD 2 Disclaimer

MHDD Data Recovery & Forensics v15 - © 2009 MHDD 3 Imaging Traditional Method

MHDD Data Recovery & Forensics v15 - © 2009 MHDD 4 What did you miss? Time you could have been playing WOW, C&C, Insert Game of Choice! Small Files that exist in the MFT! Fragmented Files! Problems with Spares Files! And you may damaged the hard drive further reading every sector especially if those are not needed!

MHDD Data Recovery & Forensics v15 - © 2009 MHDD 5 The New Way MFT Imaging & File Based Imaging This allows you to recover based on selection allowing you to be more surgical in your recovery!

MHDD Data Recovery & Forensics v15 - © 2009 MHDD 6 MetaData & MFT Files

MHDD Data Recovery & Forensics v15 - © 2009 MHDD 7 NTFS Structure (1) From Microsoft.com

MHDD Data Recovery & Forensics v15 - © 2009 MHDD 8 NTFS Structure (2) From Microsoft.com

MHDD Data Recovery & Forensics v15 - © 2009 MHDD 9 Exported MFT Records

MHDD Data Recovery & Forensics v15 - © 2009 MHDD 10 Badly Fragmented Hard Drive

MHDD Data Recovery & Forensics v15 - © 2009 MHDD 11 Concepts Restore Just Those Files Image Sectors/Clusters Use Windows to Select Folders/Files Image $MFT and $Bitmap Locate/Select Partition Tables Image MBR

MHDD Data Recovery & Forensics v15 - © 2009 MHDD 12 DeepSpar Disk Imager

MHDD Data Recovery & Forensics v15 - © 2009 MHDD 13 DeepSpar Disk Imager MFT Imaging Demo

MHDD Data Recovery & Forensics v15 - © 2009 MHDD 14 END